Becoming — Privacy Policy
Effective: 3 September 2026 · Otherdays Studio
Becoming is built around one promise: what is said in a night stays in the room. Nothing you say is ever sent to us. This policy explains exactly what that means, and is specific about the places where the wording has to be careful.
What stays on your phone — everything that matters
Conversations. If you let Becoming listen, your words are turned into text on your phone — by Apple's speech recognition, or by a speech model the app downloads once from Hugging Face. The model comes down; nothing goes up. Transcripts, the stories built from them, the people you add, your answers, favourites and taste settings are stored only on your phone. They are never uploaded to us, synced, or read by us or anyone else.
One exception, and it is Apple's, not ours: iOS transcribes on the device itself wherever the device supports it, which is every recent iPhone. Where it does not, iOS hands that audio to Apple's speech recognition instead, under Apple's privacy policy. It still never reaches us.
Voices. Audio becomes text and is then deleted. A segment still waiting to be transcribed — because a night was interrupted, or the app was closed mid-question — is held on your phone so it can be finished later. It is deleted after 72 hours whether it was transcribed or not. That ceiling is deliberate: keeping your voice never outranks losing a sentence. No audio is ever uploaded to us, and we have no way to reach it.
Your copy. If you keep a copy of your nights (Settings → Keep a copy), the file is encrypted before it leaves the app and goes wherever you put it. The key that opens it lives in your iCloud Keychain, which Apple end-to-end encrypts, so a copy opens on your other devices. We never hold the key or the copy.
What leaves your phone
Sign in with Apple. When you create an account we receive the identifier Apple issues and, if you share it, your email address. This is stored with our authentication provider (Supabase) and used only to operate your account. We never see your Apple password.
Purchases. Subscriptions and one-time purchases are processed entirely by Apple. We receive Apple's standard purchase records — what was bought, when, whether it renewed or lapsed — so that what you paid for stays unlocked across reinstalls. We never receive your payment details.
Which screens you reached. Becoming records that certain moments happened: first open, onboarding finished, a deck opened, a night started, a night finished, a story or transcript opened, the paywall seen, a purchase completed. When a night finishes, that record also carries how long was spent on each question, which questions were passed on, which sat in silence, and how long the night ran overall — identified only by our own catalogue's question id, never by the words asked or spoken. Each event is tagged with a random per-install identifier, the app version and build, and your locale — never your name, your account, or anything you said or wrote.
This is how we know whether the app works: whether people finish nights, which questions people tend to skip, or where they stop. It is our own server, not an advertising network — Becoming contains no advertising, no third-party analytics SDK, no attribution or ad tracking, and we do not share or sell any of it.
What it cannot see: any answer you gave, any word you said, any person you added, any story you made, or who among you passed on a question — that last fact stays on your phone, inside the night's own record, never sent to us. What it can see is which of our own catalogue questions a night touched, and for how long. Never what was said about them.
Whether the app is working. iOS tells us, once a day at most, if Becoming crashed or hung and how long it took to launch. We get the shape of a crash — the kind of error, the version, the iOS version — never what was on screen or what was said. It carries the same random identifier as above. This is Apple's built-in reporting, not a third-party crash tool.
Feedback you send. If you answer an in-app survey or write us a note, that text is stored on our server — and forwarded to our team's internal chat so we see it promptly — with the app version and your locale. If you are signed in, it is linked to your account so we can reply.
That is the complete list.
Deleting your data
Delete account (Settings → Delete account) permanently deletes your account from our authentication provider and erases every night, word, and person from your phone. There is no undo.
Deleting the app removes all on-device data, including any audio still waiting in the 72-hour queue.
The per-install records above carry no account identifier, so they cannot be linked back to you or retrieved on request — by us or by anyone. If you would rather we deleted the purchase and feedback records tied to your account, write to us.
Children
Becoming is intended for adults and is rated accordingly on the App Store.
Your rights
Wherever you live, you can ask us what account data we hold, ask for it corrected, or ask for it deleted. If you are in the UK or EEA, we handle your account data to perform our agreement with you (GDPR Art. 6(1)(b)) and the usage and crash records under legitimate interest in knowing whether the app works (Art. 6(1)(f)). Write to the address below and we will answer within 30 days. You may also complain to your local data protection authority.
If you are a California resident: we do not sell or share your personal information, and never have — there is nothing here to opt out of.
Account data may be processed on servers outside the country you're in. Where that crosses into or out of the UK or EEA, we rely on standard contractual clauses or an equivalent safeguard.
Security
We use standard technical safeguards — encryption in transit, encryption at rest for anything held on our server — to protect the account, purchase and feedback data described above. No system is unbreakable, but there is very little here to protect: your words never reach us in the first place.
Changes
If this policy changes, the update will be posted at this address with a new effective date. Because the architecture keeps your words on your device, changes cannot retroactively reach data we never had.
Contact
Otherdays Studio · lovish@otherdays.studio